Security / Penetration Testing Engineer – London

Cognizant

England

On-site

GBP 60,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading IT services company is seeking a Security / Penetration Testing Engineer in London. The role includes gathering security requirements, conducting API and UI/Web application penetration testing, and ensuring compliance with industry standards. Candidates must have strong hands-on experience in penetration testing and a CREST certification. This position emphasizes detailed documentation and proactive communication with stakeholders, contributing to the continuous improvement of testing methodologies.

Qualifications

  • CREST certification (CRT/CPT/CPSA or equivalent) is mandatory.
  • Strong hands-on experience in API and UI/Web application penetration testing.
  • Familiarity with ISO 27001 and PCI-DSS.

Responsibilities

  • Gather security requirements and define penetration testing scope.
  • Conduct API and UI/Web application penetration testing for vulnerabilities.
  • Prepare comprehensive test reports including risk ratings.

Skills

API penetration testing
UI/Web application penetration testing
Security standards knowledge
Documentation & Reporting
Compliance awareness

Job description

Security / Penetration Testing Engineer – London

Role will be part of our Quality Engineering & Assurance (QE&A) Practice. With more than 650 clients across industry verticals and a global footprint, Cognizant QE&A practice is a recognized thought leader in quality engineering and Assurance. As enterprises simplify, modernize and secure their legacy environments for the digital era, robust quality Engineering and assurance is essential. Quality takes an end-to-end connotation and must straddle both legacy and digital systems. Cognizant QE&A is reimagining QE&A, employing an end-to-end ecosystem approach with intelligent and automated QA processes. In so doing, increasing quality and speed to promote faster business and technology change, as well as a better customer experience.

Key Responsibilities
  • Gather security requirements and define penetration testing scope by reviewing design and interface documents.
  • Prepare detailed test plans, scenarios, and rules of engagement aligned with CREST and OWASP standards.
  • Conduct API penetration testing (REST, GraphQL, SOAP) focusing on authentication, authorization, and business logic flaws.
  • Perform UI/Web application penetration testing for vulnerabilities such as XSS, CSRF, SQL Injection, and session management issues.
  • Identify and document security issues with clear reproduction steps, evidence, and remediation recommendations.
  • Raise defects in tracking tools and collaborate with development teams for timely resolution.
  • Provide regular status updates to stakeholders and elevate risks or challenges proactively.
  • Prepare comprehensive test reports including executive summaries, technical details, and risk ratings (CVSS).
  • Support re‑testing after fixes and validate remediation effectiveness.
  • Ensure compliance with industry standards (OWASP ASVS, API Top 10, ISO 27001, PCI‑DSS).
  • Recommend security best practices and contribute to continuous improvement of testing methodologies.
  • Maintain strong documentation and communication throughout the engagement lifecycle.
Required Skills & Certifications
  • CREST certification (CRT/CPT/CPSA or equivalent) is a must.
  • Penetration Testing Expertise – Strong hands‑on experience in API and UI/Web application penetration testing.
  • Security Standards Knowledge – OWASP Top 10, OWASP API Top 10, ASVS, CVSS scoring, and CREST methodologies.
  • API Security – REST/GraphQL/SOAP testing, OAuth2/OIDC, JWT handling, rate limiting, and authorization flaws (BOLA/BFLA).
  • Web Application Security – XSS, CSRF, SQL Injection, Clickjacking, session management, CSP/CORS issues.
  • Documentation & Reporting – Ability to create detailed test plans, risk logs, and clear vulnerability reports.
  • Compliance Awareness – Familiarity with ISO 27001, PCI‑DSS, NIST guidelines.
Seniority Level
  • Associate
Employment Type
  • Full‑time
Job Function
  • Information Technology
Industries
  • IT Services and IT Consulting
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security & Penetration Tester – London
Senior Security & Penetration Tester – London

Cognizant • England

On-site
GBP 60,000 - 80,000
Penetration Tester
Penetration Tester

Big Red Recruitment • Greater London

On-site
GBP 45,000 - 75,000
Penetration Tester
Penetration Tester

Guideposts Trust Limited • Cardiff

On-site
GBP 45,000 - 65,000
Cyber Security Consultant (Penetration Tester)
Cyber Security Consultant (Penetration Tester)

Moore Kingston Smith LLP • Greater London

On-site
GBP 45,000 - 55,000
Cyber Security Consultant (Penetration Tester)
Cyber Security Consultant (Penetration Tester)

Moore Kingston Smith • Greater London

On-site
GBP 45,000 - 55,000
Penetration Tester
Penetration Tester

4Square Recruitment Ltd • Manchester

Hybrid
GBP 40,000 - 60,000
Annual bonus up to 10%
25 days holiday + bank holidays
Regular team events & socials
Pen Tester
Pen Tester

Remarkable Jobs • Greater London

Hybrid
GBP 45,000 - 60,000
Penetration Tester
Penetration Tester

Oscar • Bristol

On-site
GBP 60,000 - 80,000
Funded certifications
Access to modern tooling
Performance-based incentives
Application Security Consultant
Application Security Consultant

Cytix • Manchester

Hybrid
GBP 40,000 - 50,000
Private Healthcare (inc. dental, optical, and hearing)
Unlimited Holidays
EMI share options
Penetration Tester
Penetration Tester

Ultima • Reading

On-site
GBP 45,000 - 60,000
25 days’ holiday plus bank holidays
2 volunteering days
1 personal day
+3